GDPR and Data Retention – Aspire Training

GDPR and Data Retention

GDPR requires that consumer data be kept private in terms of how it is disposed of, produced and managed.

GDPR guidance is that “personal data may only be kept in a form that permits identification of the individual for no longer than is necessary for the purposes for which it was processed”.

All assessment materials at Aspire Training are retained until at least the appeals period has expired.

We respect both staff and learner privacy and their rights to control their personal data. We will be clear about what data we collect and why we collect it. This explains the personal information we collect, why we collect it, how we will use it and how we protect it.

We collect personal data to provide advice, training and certification on Further Education and Training Services.

Aspire Training is a Controller of the personal data that learners (the data subject) provide us. We can collect the following types of personal data from learners:

Personal Data:

– First Name

– Learner Last Name

– Date of Birth

– PPSN

– Phone Number

– Address

– All previous addresses

– Email Address

– Proof of Identity

– Proof of Address

– Medical Card ID (if applicable)

– Job Title

– Professional Experience

– Educational Qualifications

– Person’s Interests (Course)

– Qualifications

– Video recordings where applicable as evidence of skills

Sensitive Personal Data, with your consent, regarding Training Needs Analysis or Reasonable Accommodation Requests:

– Psychological assessments

– Special Education Needs’ files

– Garda vetting details

Payment details:

– Credit / Debit Card details

– Bank details in the case of Direct Debits / Refunds

Protection of personal data remains a priority. We will only share personal information where the law allows, and we always aim to share the minimum data necessary to achieve the purpose required

Why We Collect Personal Data

We use the personal data learners share with us to process your interest requests and to provide you with training advice and for business administration, educational services through teaching, research and associated academic and administrative activities, for example, recruitment of learners, provision of programmes of study, examinations, engaging with accrediting bodies and Government agencies such as Quality and Qualifications Ireland (QQI), and the Department of Education & Skills.

We rely on the following legal bases to process personal data.

– Contract – When learners engage and voluntarily provide personal data to enquire about or purchase our products or services.

– Legitimate Interest – To respond to queries and the general administration of our business

– Consent – To process special category data.

– Legal Obligation

Sharing & Disclosure

We strive to keep personal data safe and only share it when necessary. We recognise that learners have a right to know that the information they share with Aspire Training is maintained confidentially.

We do not rent or sell personal data to anyone.

However in certain limited circumstances, obtaining consent may be impractical, not possible, or undesirable.  Examples could include:

– Where the disclosure is required by law.

– Where the disclosure is required to prevent, detect, or investigate offences.

– Where the disclosure is required urgently to prevent injury, or other damage to the health of a person, or otherwise to protect the vital interests of the learner.

We Do With Personal Data

We process your personal data onsite in Aspire Training.

We have agreements in place with various providers to protect personal data. We use e-mail services to conduct evaluations, circulate our upcoming courses and to follow up on enquiries learners have made. We use a cloud based service to host online classes.

Your data is also processed through QQI – Quality Qualifications Ireland to submit your results for certification.

We have agreements in place with multiple providers to protect personal data.

How Long We Keep Personal Data

Aspire Training needs to maintain some records relating to learners after they complete in order to provide services to them as a previous learner of Aspire Training and for the reasons set out below:

– Verifying your award

– Providing transcripts of your marks

– Opportunities for further study

– Academic references

– Careers support

– Revenue Commissioners

– QQI

– Where we are under a duty to disclose personal information in order to comply with any legal obligation (for example to government bodies and law enforcement agencies).

– Personal information may also be processed if it is necessary in the defence of a legal claim. We will not delete personal information if relevant to an investigation or a dispute. It will continue to be stored until those issues are fully resolved.

Keeping Personal Data Secure

We use appropriate technical, organisational, and administrative security measures to protect all personal data we hold in our records and keep it secure.

We are committed to ensuring that your personal data is secure with us and with the data processors who act on our behalf. We are continuously taking technical and organisational steps to better protect your information. Data Protection training is mandatory for all staff.

We take appropriate measures under the laws that apply, to ensure your data is safe.

– IT

– Emails & other Electronic Data is stored in secure cloud system

– AntiVirus Software is used on all IT Systems

– Encryption is enabled on all systems holding Personal Data

– A Firewall assists against Network Intrusion

– WiFi is secure

– Document Storage

– Documents are stored in a locked Office in Individual covered Files

– Data is managed safely and not left in areas where non relevant employees can access

– Any data which might be viewed as in any way sensitive is stored in locked cabinets in the office

– Data Disposal

– Although Aspire Training does not hold sensitive data, we engage with a GDPR Compliant Professional Shredding Company and safety/securely dispose of the Personal Data we hold to ensure compliance – see section on Data disposal

– Calls relating to Personal Data

– If a learner contacts us about their information, we may need to ask them to identify themselves and furnish proof of identity – this is to help protect your information.

How Long We Keep Personal Data

We have policy based and regulatory obligations that mean we must keep learner data while they are an active learner and for certain periods of time after they complete a programme. Those periods depend on the nature of the work we have done for you.

– General Data Retention Policy (Clients)

– We retain general training data for a period of 5 years

– General Data Retention Policy (Contractors/Trainers/Vendors)

– We retain personal data of the above for the duration of working relationship (+12 months)

– Accreditation Requirements

– QQI – 6 Years

– Legal Obligations

– Revenue – 6 Years

End of Life Policy

Once the period of stated storage is complete, or based on a Request to delete personal data (presuming we have no legal or statutory obligation to retain it) – it is our policy to have personal data securely disposed of – through annually scheduled contracts with our professional shredding company.

This service will dispose of personal data such as has been collected on Attendance Logs, Forms, Feedback, Examinations and more.

Data will be securely deleted from the following media:

– Paper Based Files

– CRM & Database Systems

– Electronic Storage – including Hard Disks, External Hard Drives, Memory Sticks & Email

– Back-up Data will be deleted also in relation to these files

Learner Rights

Learner rights relating to personal data include:

– to be informed (via the Learner Handbook and other communications) – please contact the Training and Administration Team with any questions or concerns regarding data protection

– to request access to Personal Data held by Aspire Training, and to have any incorrect Personal Data rectified

– where appropriate, to the restriction of processing concerning the learner or to object to processing

– to have Personal Data erased, where appropriate

– to data portability regarding certain automated Personal Data

– to restrict the use of the data we hold and the right to object to Aspire Training using their data

Learner Responsibilities

Updating their details:

The GDPR requires that personal data is accurate.  Aspire Training is to be informed if personal data changes, such as a change of address or telephone number. If we do not have the correct contact details we may be unable to provide learners with important information they require, for example, an exam date or deadline and this could result in serious consequences, or a certificate could be posted to the wrong address.